White paper
Sovereign AI: keeping your data at home (Law 09-08, GDPR, AI Act)
Your teams already use generative AI, often through consumer tools. Every document pasted into a chat may leave the company. Sovereign AI means getting the benefits of these tools without losing control of your data.

The problem: data leaving quietly
A contract to summarise, a customer file to analyse, a letter to rephrase: pasting this content into a public AI service means handing it to a third party, sometimes hosted outside Morocco, and sometimes reused to train its models depending on the terms of use. The company loses track of its data, and takes on legal risk if that data is personal.
Banning AI does not work: usage carries on, just without control. The right answer is to offer an alternative that is just as convenient, within a controlled framework.
What “sovereign AI” means
In practical terms, AI is sovereign when you control four things:
- Where
- where your data is stored and processed: your servers, a cloud in Morocco, or a chosen region with contractual guarantees.
- Who
- the people and providers who can access it, and what they are allowed to do with it.
- What
- the model used, its version and its behaviour, tested on your use cases.
- How
- traceability: who asked what, with which sources, and what answer was given.
Law 09-08: the Moroccan framework
Law 09-08 governs the processing of personal data in Morocco, under the supervision of the CNDP. Indexing documents that contain names, emails or customer files in an AI assistant is processing within the meaning of the law. The main points to watch:
- Purpose and proportionality: data must be collected for a specific purpose and limited to what is necessary.
- Prior formalities: the processing must be declared to the CNDP, or authorised when it involves sensitive data.
- Transfers abroad: only allowed to a country ensuring adequate protection, with CNDP authorisation, or in the cases provided for by the law (Articles 43 and 44). An AI service hosted outside Morocco may therefore involve a transfer that must be framed.
- Individuals’ rights: access, rectification and objection must remain possible, including on indexed data.
- Security: the controller must take appropriate measures to protect data against unauthorised access or leaks.
GDPR: as soon as you process European data
The GDPR applies to companies established in the European Union, but also to companies that, from Morocco, offer services to people in the Union or monitor their behaviour. If you have customers, employees or a subsidiary in Europe, you are probably concerned.
- Morocco is not covered by a European Commission adequacy decision: a data transfer from the Union to Morocco must therefore rely on appropriate safeguards, such as standard contractual clauses.
- High-risk processing (sensitive data, evaluating individuals, monitoring) may require a prior data protection impact assessment (DPIA).
- AI providers act as processors: you need a contract that frames their role (Article 28).
The AI Act: the EU regulation on AI
Regulation (EU) 2024/1689, the AI Act, entered into force on 1 August 2024. It also applies to companies outside the Union when the output of their AI system is used in the Union. It classifies uses by risk level:
- Unacceptable risk
- Practices banned since 2 February 2025 (social scoring, manipulation, some biometric identification…).
- High risk
- Recruitment, credit scoring, access to essential services, education… Heavy obligations: risk management, data quality, documentation, human oversight.
- Limited risk
- Transparency obligations: tell users they are interacting with an AI, label generated content.
- Minimal risk
- Most internal uses (summaries, document search): no specific obligation beyond general rules.
The timeline is staggered: bans and the staff training obligation (“AI literacy”) since February 2025, rules for general-purpose models since August 2025, then most other obligations from August 2026. The European Commission has proposed adjustments to this timeline: check the deadlines in force for your use cases.
This document gives general guidance and is not legal advice. For a specific project, have your analysis validated by your counsel or data protection officer.
An architecture that keeps your data at home
The most requested use case is the assistant on your documents (known as “RAG”, retrieval-augmented generation): the AI answers your teams’ questions from your procedures, contracts or knowledge bases, citing its sources. A sovereign architecture rests on a few principles:
- Documents stay within your perimeter: storage and search index hosted on your premises or in a cloud whose location you choose.
- A controlled model: an open model hosted in your environment, or an AI service in a chosen region with a contractual commitment not to retain or reuse your data.
- Access rights are enforced: users only get answers from documents they are already allowed to see.
- Every answer cites its sources, so users can check.
- A human approves sensitive actions: the AI suggests, a person decides.
- Everything is logged: questions, sources used, answers, for audit and improvement.
The governance checklist
- Inventory current AI use in the company, including consumer tools.
- Classify your data (public, internal, confidential, personal, sensitive) and decide which can be processed, and where.
- Write a simple AI usage policy for staff.
- Record the processing in your register, complete the CNDP formalities and, if the GDPR applies, assess whether an impact assessment is needed.
- Frame providers contractually (location, retention, sub-processing).
- Test the assistant: answer quality, resistance to prompt injection, enforcement of access rights.
- Train your teams and appoint an owner for the system.
Where to start
Pick a narrow use case with high value and low-sensitivity data (for example an internal procedures base), and put it into production within a controlled framework. Six weeks of pilot will teach you more than six months of deliberation. FIDO TEAM designs and hosts RAG assistants and AI agents compliant with Law 09-08: let’s explore a use case together.
A project, a question?
An expert reply within 24 business hours, a detailed quote within 5 days, no commitment.


